Sovereign by architecture, not by claim.
Local-first means compliance is the default state, not a configuration you have to keep maintaining. We're a Dutch company building on European infrastructure with European primary providers. The EU AI Act isn't something we adapt to, it's the frame we designed inside.
Data stays on your machine
Local mode means prompts, completions, agent memory, and capability data never leave the device. The cloud is opt-in per prompt and per model, not a global setting buried in the defaults.
No US CLOUD Act exposure
Atypisch is registered in the Netherlands. Soriku Cloud runs on European infrastructure (Nefos in the EU region). Mistral is the recommended remote primary. US providers are available too, by your choice and with your own key.
EU AI Act, designed-in
Transparency, traceability, human oversight, and risk-tier handling are part of the engine, not bolted on afterwards. Every routed prompt has provenance, so you see which model answered and why. Enterprise includes formal compliance support.
GDPR by default
Local mode means prompts, completions, and agent memory stay on your machine, so for most work there is no third-party processing to account for. When you do use the cloud it is opt-in per prompt, with data-subject rights, retention, and breach handling written down rather than assumed.
API keys never leave your machine
In hosted Soriku Cloud, your remote-provider keys live encrypted in your workspace. They're decrypted at request time, used, then dropped. No long-term server-side storage of your credentials.
What you can put in a procurement form
- Data processor: Atypisch, Netherlands
- Hosting region: EU only (configurable)
- Primary external model: Mistral (Paris)
- Local mode: no data leaves the device
- DPA available on request
- SOC 2 Type II: in progress (target Q4 2026)
- ISO 27001: planned 2027
- Subprocessors: listed in the DPA and updated when they change
- AI Act risk tier: limited risk (general-purpose tool)
Need a DPA or vendor assessment?
Enterprise customers get formal compliance support, including AI Act risk-tier documentation tailored to your use case.